Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 373

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Altman and Amodei expected to join UN Security Council meeting about AI
Nvidia options are doing something unusual ahead of two catalysts. Here's how one trader is playing it
Here's who we know is going to the Trump-Xi dinner so far
Trump discloses more than 1,100 July trades, including up to $25 million each in sales of Microsoft, Amazon
OpenAI proposes development of global AI standards to guide alignment, RSI
Movie: Resident Evil: Extinction
Trapped in minimum payments? These products can help you get out of credit card debt
Flight disruptions ease at Newark, Philadelphia airports following equipment outage
Buy the dip on GE Healthcare, says Needham
Carer Stress vs The Stress of Needing Care